<?php

namespace App\Http\Middleware;

use Closure;

class CorsMiddleware
{
    /**
     * Handle an incoming request.
     *
     * @param  \Illuminate\Http\Request $request
     * @param  \Closure $next
     * @return mixed
     */
    public function handle($request, Closure $next)
    {
        $response = $next($request);

        /**
         * 不限制权限
         */

        $response->header('Access-Control-Allow-Origin', '*');
        $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, Accept, multipart/form-data, application/json, token');
        $response->header('Access-Control-Allow-Methods', 'GET, POST, DELETE, PUT, OPTIONS');
        $response->header('Access-Control-Allow-Credentials', 'true');



        /**
         * 限制权限
         */

        //        //当前访问地址
        //        $origin = $request->server('HTTP_ORIGIN') ? $request->server('HTTP_ORIGIN') : '';
        //
        //        //开放权限地址
        //        $allow_origin = [
        //            'http://www.gupiaoadmin.com',
        //            'http://www.gupiao.com',
        //        ];
        //
        //        if (in_array($origin, $allow_origin)) {
        //            $response->header('Access-Control-Allow-Origin', $origin);
        //            $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, Accept, multipart/form-data, application/json, token');
        //            $response->header('Access-Control-Allow-Methods', 'GET, POST, DELETE, PUT, OPTIONS');
        //            $response->header('Access-Control-Allow-Credentials', 'true');
        //        }

        return $response;
    }
}
